Palo Alto Networks Certified Cloud Security Engineer (PCCSE)Prisma Cloud PlatformEasy

A security operations center (SOC) analyst needs to integrate Prisma Cloud with their existing Security Information and Event Management (SIEM) system for centralized logging and correlation of security events. The SIEM requires events to be forwarded via a standard syslog protocol. Which Prisma Cloud integration method should the analyst configure?

  1. ASyslog Export
  2. BWebhook Integration
  3. CCloud Storage Export
  4. DAPI Call to SIEM
Show answer & explanation

Correct answer: A. Syslog Export

For integrating with a SIEM system that requires events via standard syslog, Prisma Cloud's direct syslog export functionality is the most suitable and efficient method. This allows for real-time forwarding of alerts and audit logs.

Why the other options are wrong

  • B. Webhooks are typically HTTP-based and send data to an endpoint, not directly via syslog protocol.
  • C. Cloud storage export is for archival or batch processing, not real-time SIEM integration via syslog.
  • D. While possible, an API call would likely require custom development and is not the standard way for syslog.

Prisma Cloud Syslog Export

A Prisma Cloud feature that allows real-time forwarding of security alerts, audit logs, and other event data to an external syslog server, typically a SIEM.

  • Supports standard syslog protocols (UDP, TCP, TLS).
  • Enables centralized logging and security event correlation.
  • Configurable for various event types (alerts, audit logs).

Memory trick: To SIEM, send it with Syslog, simple and sound.

More Prisma Cloud Platform questions